VYPR

Express Cart

by Express Cart Project

Source repositories

CVEs (4)

  • CVE-2018-16483HigFeb 1, 2019
    risk 0.57cvss 8.8epss 0.01

    A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

  • CVE-2018-3758HigJun 7, 2018
    risk 0.52cvss 8.8epss 0.27

    Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

  • CVE-2020-22403HigAug 12, 2021
    risk 0.50cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.

  • CVE-2021-32573MedMay 11, 2021
    risk 0.31cvss 4.8epss 0.01

    The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.